CVE-2026-49980
CRITICALRclone 1.46.0 to < 1.74.3 - Unauthenticated Command Execution via rc-serve
Title source: manualDescription
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-49980
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2492478
Scores
CVSS v3
9.8
EPSS
0.0075
EPSS Percentile
51.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
CWE-78
Status
published
Products (3)
rclone/rclone
1.46 - 1.74.3
rclone/rclone
1.46.0 - 1.74.3Go
rclone/rclone
>= 1.46.0, < 1.74.3
Published
Jun 24, 2026
Tracked Since
Jun 25, 2026